This page describes how Xenmark processes data and which third-party processors are involved in operating the service. It is the subprocessor register referenced in the Xenmark Data Processing Agreement (DPA). For questions, contact [email protected].
1. Data controller
Controller: Xenmark
Legal entity: Xenmark AS
Org. nr.: 937 996 799 · Norway
Contact: [email protected]
Application: my.xenmark.app
Marketing site: www.xenmark.app
2. What data is processed
The Xenmark marketing site (www.xenmark.app) is static and does not collect personal data through forms or accounts. All personal data processing happens inside the Xenmark application (my.xenmark.app).
Inside the application, Xenmark processes:
- Account data — name, email address, and authentication credentials.
- Project and review data — projects, drawings, revisions, comments, replies, statuses, and member assignments you create or upload.
- Billing data — subscription and payment information handled through Stripe.
- Operational logs — basic usage and error logs needed to run the service reliably.
3. Subprocessors
Xenmark relies on the following third-party processors to operate the service. Each processor handles only the data necessary for their specific function.
Cloudflare
Provides domain registration and DNS management, Cloudflare Pages hosting for the marketing site, access protection where enabled, and related edge and security services for xenmark.app. Also provides R2 object storage for project files and attachments, and Workers for token-gated storage access and serverless processing. Cloudflare may process limited technical request data such as IP address, user agent, request URL, and security/access logs.
Backblaze
Provides encrypted operational backup storage for selected Xenmark project files, attachments, and related object metadata. Backblaze is used for internal recovery, integrity verification, and incident response if production storage or application errors cause accidental loss or corruption. These backups are not a customer-facing archive or self-service restore feature. Access is restricted to authorised Xenmark administrative/support operations, and backup copies are retained and deleted according to Xenmark's backup and deletion procedures.
Supabase
Handles user authentication, the relational database (projects, drawings, revisions, comments, members), Edge Functions for server-side logic, and Vault for secrets management.
Resend
Delivers transactional emails including account notifications, archive expiry reminders, and other service-related messages. Resend receives the recipient email address and the email content needed to deliver each message.
Stripe
Handles billing and payment processing for paid plans. Stripe processes payment details directly. Xenmark does not store full card numbers or raw payment credentials. No Customer project content is authorised to be sent.
Google Fonts
Delivers web fonts (Instrument Serif, Geist, Geist Mono) used on the marketing site and application. A visitor's browser connects to fonts.googleapis.com and fonts.gstatic.com to load the fonts. Google may receive IP address and ordinary HTTP request metadata. No Customer project content is transmitted.
UNPKG
Delivers the pdf-lib JavaScript library used in the application for PDF rendering and export. A user's browser connects to unpkg.com to load the library. UNPKG may receive IP address and ordinary HTTP request metadata. No Customer project content is transmitted.
4. Data transfers
Xenmark uses processors that may operate infrastructure in multiple regions. The specific data residency and transfer details for each processor are governed by their respective data processing agreements and privacy policies.
5. Your rights
You may request access to, correction of, or deletion of personal data associated with your account. To submit a data request, email [email protected] or use the contact page.
6. Changes to this page
When this page is materially changed, the "Last updated" date near the top of the page will be updated. Xenmark does not maintain a public change log for this page.